<!--

    Copyright © 2016-2025 The Thingsboard Authors

    Licensed under the Apache License, Version 2.0 (the "License");
    you may not use this file except in compliance with the License.
    You may obtain a copy of the License at

        http://www.apache.org/licenses/LICENSE-2.0

    Unless required by applicable law or agreed to in writing, software
    distributed under the License is distributed on an "AS IS" BASIS,
    WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
    See the License for the specific language governing permissions and
    limitations under the License.

-->
<mat-card appearance="outlined" class="settings-card">
  <mat-card-header>
    <mat-card-title>
      <span class="mat-headline-5" translate>admin.security-settings</span>
    </mat-card-title>
    <span class="flex-1"></span>
    <div tb-help="securitySettings"></div>
  </mat-card-header>
  <mat-progress-bar color="warn" mode="indeterminate" *ngIf="isLoading$ | async">
  </mat-progress-bar>
  <div style="height: 4px;" *ngIf="!(isLoading$ | async)"></div>
  <mat-card-content>
    <form [formGroup]="securitySettingsFormGroup" (ngSubmit)="save()" autocomplete="off">
      <fieldset [disabled]="isLoading$ | async">
        <fieldset class="fields-group">
          <legend class="group-title" translate>admin.general-policy</legend>
          <mat-form-field class="mat-block">
            <mat-label translate>admin.max-failed-login-attempts</mat-label>
            <input matInput type="number"
                   formControlName="maxFailedLoginAttempts"
                   step="1"
                   min="0"/>
            <mat-error *ngIf="securitySettingsFormGroup.get('maxFailedLoginAttempts').hasError('min')">
              {{ 'admin.minimum-max-failed-login-attempts-range' | translate }}
            </mat-error>
          </mat-form-field>
          <mat-form-field class="mat-block">
            <mat-label translate>admin.user-lockout-notification-email</mat-label>
            <input matInput type="email"
                   formControlName="userLockoutNotificationEmail"/>
          </mat-form-field>
          <mat-form-field class="mat-block">
            <mat-label translate>admin.user-activation-token-ttl</mat-label>
            <input matInput type="number"
                   formControlName="userActivationTokenTtl"
                   step="1"
                   min="1"
                   max="24"/>
            <mat-error *ngIf="securitySettingsFormGroup.get('userActivationTokenTtl').hasError('min')">
              {{ 'admin.user-activation-token-ttl-range' | translate }}
            </mat-error>
            <mat-error *ngIf="securitySettingsFormGroup.get('userActivationTokenTtl').hasError('max')">
              {{ 'admin.user-activation-token-ttl-range' | translate }}
            </mat-error>
          </mat-form-field>
           <mat-form-field class="mat-block">
            <mat-label translate>admin.password-reset-token-ttl</mat-label>
            <input matInput type="number"
                  formControlName="passwordResetTokenTtl"
                  step="1"
                  min="1"
                  max="24"/>
            <mat-error *ngIf="securitySettingsFormGroup.get('passwordResetTokenTtl').hasError('min')">
              {{ 'admin.password-reset-token-ttl-range' | translate }}
            </mat-error>
            <mat-error *ngIf="securitySettingsFormGroup.get('passwordResetTokenTtl').hasError('max')">
              {{ 'admin.password-reset-token-ttl-range' | translate }}
            </mat-error>
          </mat-form-field>
          <mat-form-field class="mat-block">
            <mat-label translate>admin.mobile-secret-key-length</mat-label>
            <input matInput type="number"
                   formControlName="mobileSecretKeyLength"
                   step="1"
                   min="1"/>
            <mat-error *ngIf="securitySettingsFormGroup.get('mobileSecretKeyLength').hasError('min')">
              {{ 'admin.mobile-secret-key-length-range' | translate }}
            </mat-error>
          </mat-form-field>
        </fieldset>

        <fieldset class="fields-group">
          <legend class="group-title" translate>admin.password-policy</legend>
          <section formGroupName="passwordPolicy">
            <div class="flex flex-row xs:flex-col gt-xs:gap-2">
              <mat-form-field class="mat-block flex-1">
                <mat-label translate>admin.minimum-password-length</mat-label>
                <input matInput type="number"
                       formControlName="minimumLength"
                       step="1"
                       min="6"
                       max="50"
                       required/>
                <mat-error *ngIf="securitySettingsFormGroup.get('passwordPolicy.minimumLength').hasError('required')">
                  {{ 'admin.minimum-password-length-required' | translate }}
                </mat-error>
                <mat-error *ngIf="securitySettingsFormGroup.get('passwordPolicy.minimumLength').hasError('min')">
                  {{ 'admin.minimum-password-length-range' | translate }}
                </mat-error>
                <mat-error *ngIf="securitySettingsFormGroup.get('passwordPolicy.minimumLength').hasError('max')">
                  {{ 'admin.minimum-password-length-range' | translate }}
                </mat-error>
              </mat-form-field>
              <mat-form-field class="mat-block flex-1" subscriptSizing="dynamic">
                <mat-label translate>admin.maximum-password-length</mat-label>
                <input matInput type="number" formControlName="maximumLength" step="1" min="6"/>
                <mat-hint></mat-hint>
                <mat-error *ngIf="securitySettingsFormGroup.get('passwordPolicy.maximumLength').hasError('min')">
                  {{ 'admin.maximum-password-length-min' | translate }}
                </mat-error>
                <mat-error *ngIf="securitySettingsFormGroup.get('passwordPolicy.maximumLength').hasError('lessMin')">
                  {{ 'admin.maximum-password-length-less-min' | translate }}
                </mat-error>
              </mat-form-field>
            </div>
            <div class="flex flex-row xs:flex-col gt-xs:gap-2">
              <mat-form-field class="mat-block flex-1">
                <mat-label translate>admin.minimum-uppercase-letters</mat-label>
                <input matInput type="number"
                       formControlName="minimumUppercaseLetters"
                       step="1"
                       min="0"/>
                <mat-error
                  *ngIf="securitySettingsFormGroup.get('passwordPolicy.minimumUppercaseLetters').hasError('min')">
                  {{ 'admin.minimum-uppercase-letters-range' | translate }}
                </mat-error>
              </mat-form-field>
              <mat-form-field class="mat-block flex-1">
                <mat-label translate>admin.minimum-lowercase-letters</mat-label>
                <input matInput type="number"
                       formControlName="minimumLowercaseLetters"
                       step="1"
                       min="0"/>
                <mat-error
                  *ngIf="securitySettingsFormGroup.get('passwordPolicy.minimumLowercaseLetters').hasError('min')">
                  {{ 'admin.minimum-lowercase-letters-range' | translate }}
                </mat-error>
              </mat-form-field>
            </div>
            <div class="flex flex-row xs:flex-col gt-xs:gap-2">
              <mat-form-field class="mat-block flex-1">
                <mat-label translate>admin.minimum-digits</mat-label>
                <input matInput type="number"
                       formControlName="minimumDigits"
                       step="1"
                       min="0"/>
                <mat-error *ngIf="securitySettingsFormGroup.get('passwordPolicy.minimumDigits').hasError('min')">
                  {{ 'admin.minimum-digits-range' | translate }}
                </mat-error>
              </mat-form-field>
              <mat-form-field class="mat-block flex-1">
                <mat-label translate>admin.minimum-special-characters</mat-label>
                <input matInput type="number"
                       formControlName="minimumSpecialCharacters"
                       step="1"
                       min="0"/>
                <mat-error
                  *ngIf="securitySettingsFormGroup.get('passwordPolicy.minimumSpecialCharacters').hasError('min')">
                  {{ 'admin.minimum-special-characters-range' | translate }}
                </mat-error>
              </mat-form-field>
            </div>
            <div class="flex flex-row xs:flex-col gt-xs:gap-2">
              <mat-form-field class="mat-block flex-1">
                <mat-label translate>admin.password-expiration-period-days</mat-label>
                <input matInput type="number"
                       formControlName="passwordExpirationPeriodDays"
                       step="1"
                       min="0"/>
                <mat-error
                  *ngIf="securitySettingsFormGroup.get('passwordPolicy.passwordExpirationPeriodDays').hasError('min')">
                  {{ 'admin.password-expiration-period-days-range' | translate }}
                </mat-error>
              </mat-form-field>
              <mat-form-field class="mat-block flex-1">
                <mat-label translate>admin.password-reuse-frequency-days</mat-label>
                <input matInput type="number"
                       formControlName="passwordReuseFrequencyDays"
                       step="1"
                       min="0"/>
                <mat-error
                  *ngIf="securitySettingsFormGroup.get('passwordPolicy.passwordReuseFrequencyDays').hasError('min')">
                  {{ 'admin.password-reuse-frequency-days-range' | translate }}
                </mat-error>
              </mat-form-field>
            </div>
            <div class="flex flex-row xs:flex-col gt-xs:gap-2">
              <mat-checkbox class="flex-1" formControlName="allowWhitespaces" style="margin-bottom: 16px">
                <mat-label translate>admin.allow-whitespace</mat-label>
              </mat-checkbox>
              <mat-checkbox class="flex-1" formControlName="forceUserToResetPasswordIfNotValid" style="margin-bottom: 16px">
                <mat-label tb-hint-tooltip-icon="{{'admin.force-reset-password-if-no-valid-hint' | translate}}">
                  {{'admin.force-reset-password-if-no-valid' | translate}}
                </mat-label>
              </mat-checkbox>
            </div>
          </section>
        </fieldset>
        <div class="flex flex-row flex-wrap items-center justify-end gap-2" style="margin-top: 16px">
          <button mat-button color="primary"
                  [disabled]="securitySettingsFormGroup.pristine"
                  (click)="discardSetting()"
                  type="button">{{'action.undo' | translate}}
          </button>
          <button mat-button mat-raised-button color="primary" [disabled]="(isLoading$ | async) || securitySettingsFormGroup.invalid || !securitySettingsFormGroup.dirty"
                  type="submit">{{'action.save' | translate}}
          </button>
        </div>
      </fieldset>
    </form>
  </mat-card-content>
</mat-card>
<mat-card appearance="outlined" class="settings-card">
  <mat-card-header>
    <mat-card-title>
      <span class="mat-headline-5" translate>admin.jwt.security-settings</span>
    </mat-card-title>
    <span class="flex-1"></span>
    <div tb-help="jwtSecuritySettings"></div>
  </mat-card-header>
  <mat-card-content style="padding-top: 16px;">
    <form [formGroup]="jwtSecuritySettingsFormGroup" (ngSubmit)="saveJwtSettings()" autocomplete="off">
      <fieldset [disabled]="isLoading$ | async" class="flex flex-col gap-2">
        <div class="flex flex-row gap-2 xs:flex-col">
          <mat-form-field class="mat-block flex-1" subscriptSizing="dynamic">
            <mat-label translate>admin.jwt.issuer-name</mat-label>
            <input matInput required formControlName="tokenIssuer"/>
            <mat-error *ngIf="jwtSecuritySettingsFormGroup.get('tokenIssuer').hasError('required')">
              {{ 'admin.jwt.issuer-name-required' | translate }}
            </mat-error>
          </mat-form-field>
          <mat-form-field class="mat-block flex-1" subscriptSizing="dynamic">
            <mat-label translate>admin.jwt.signings-key</mat-label>
            <input matInput (focus)="markAsTouched()" required formControlName="tokenSigningKey"/>
            <button type="button"
                    style="line-height: 32px"
                    matSuffix
                    mat-button
                    (click)="generateSigningKey()"
                    color="primary">
              {{ 'admin.jwt.generate-key' | translate }}
            </button>
            <mat-hint translate>admin.jwt.signings-key-hint</mat-hint>
            <mat-error *ngIf="jwtSecuritySettingsFormGroup.get('tokenSigningKey').hasError('required')">
              {{ 'admin.jwt.signings-key-required' | translate }}
            </mat-error>
            <mat-error *ngIf="jwtSecuritySettingsFormGroup.get('tokenSigningKey').hasError('base64')">
              {{ 'admin.jwt.signings-key-base64' | translate }}
            </mat-error>
            <mat-error *ngIf="jwtSecuritySettingsFormGroup.get('tokenSigningKey').hasError('minLength')">
              {{ 'admin.jwt.signings-key-min-length' | translate }}
            </mat-error>
          </mat-form-field>
        </div>
        <div class="flex flex-row gap-2 xs:flex-col">
          <mat-form-field class="mat-block flex-1" subscriptSizing="dynamic">
            <mat-label translate>admin.jwt.expiration-time</mat-label>
            <input matInput type="number" required
                   formControlName="tokenExpirationTime"
                   step="1"
                   min="60"/>
            <mat-hint></mat-hint>
            <mat-error *ngIf="jwtSecuritySettingsFormGroup.get('tokenExpirationTime').hasError('required')">
              {{ 'admin.jwt.expiration-time-required' | translate }}
            </mat-error>
            <mat-error *ngIf="jwtSecuritySettingsFormGroup.get('tokenExpirationTime').hasError('max')">
              {{ 'admin.jwt.expiration-time-max' | translate }}
            </mat-error>
            <mat-error *ngIf="jwtSecuritySettingsFormGroup.get('tokenExpirationTime').hasError('min')">
              {{ 'admin.jwt.expiration-time-min' | translate }}
            </mat-error>
          </mat-form-field>
          <mat-form-field class="mat-block flex-1" subscriptSizing="dynamic">
            <mat-label translate>admin.jwt.refresh-expiration-time</mat-label>
            <input matInput type="number" required
                   formControlName="refreshTokenExpTime"
                   step="1"
                   min="900"/>
            <mat-hint></mat-hint>
            <mat-error *ngIf="jwtSecuritySettingsFormGroup.get('refreshTokenExpTime').hasError('required')">
              {{ 'admin.jwt.refresh-expiration-time-required' | translate }}
            </mat-error>
            <mat-error *ngIf="jwtSecuritySettingsFormGroup.get('refreshTokenExpTime').hasError('max')">
              {{ 'admin.jwt.refresh-expiration-time-max' | translate }}
            </mat-error>
            <mat-error *ngIf="jwtSecuritySettingsFormGroup.get('refreshTokenExpTime').hasError('min')">
              {{ 'admin.jwt.refresh-expiration-time-min' | translate }}
            </mat-error>
            <mat-error *ngIf="jwtSecuritySettingsFormGroup.get('refreshTokenExpTime').hasError('lessToken')">
              {{ 'admin.jwt.refresh-expiration-time-less-token' | translate }}
            </mat-error>
          </mat-form-field>
        </div>
        <div class="flex flex-row flex-wrap items-center justify-end gap-2">
          <button mat-button color="primary"
                  [disabled]="jwtSecuritySettingsFormGroup.pristine"
                  (click)="discardJwtSetting()"
                  type="button">{{'action.undo' | translate}}
          </button>
          <button mat-raised-button color="primary"
                  [disabled]="(isLoading$ | async) || jwtSecuritySettingsFormGroup.invalid || !jwtSecuritySettingsFormGroup.dirty"
                  type="submit">{{'action.save' | translate}}
          </button>
        </div>
      </fieldset>
    </form>
  </mat-card-content>
</mat-card>
